Privacy Policy
What Shortsly processes, why it is needed, who receives it and your choices.
Last updated September 10, 2026
Controller and contact
Volodymyr Markiv, Schnirchgasse 13, Wien, Austria, is the controller for the personal data described in this policy. Privacy requests can be sent to support@shortsly.io.
This policy applies to shortsly.io, the Shortsly application and your account. A third-party service you choose to use has its own privacy notice.
Data we process
Account and billing data: your email, authentication identifiers, profile details, plan, credit balance, transaction and subscription references. Stripe receives payment details; Shortsly does not store full card details.
Creator content: scripts, prompts, settings, uploaded media, selected voices, generated images, audio, captions, projects and exports. A request may contain up to 20 files; current single-file limits are 10 MB for images, 64 MB for audio and 100 MB for video. Live account media is limited to 10.0 GB per user.
Technical and usage data: device and browser information, IP-derived information, request and error logs, feature interactions, generation status and credit-ledger records.
Purposes and legal bases
We process account and creator content to provide, support and bill for the service you request and to enforce usage limits; the legal basis is performance of our contract with you.
We process transaction and compliance records to meet accounting, tax, legal and regulatory obligations.
We process security logs, abuse signals and limited product analytics for our legitimate interests in protecting Shortsly, preventing fraud, diagnosing failures and improving the workflow. Where consent is legally required for non-essential analytics or storage, we request it before using them.
Recipients and international transfers
We use service providers including Clerk (authentication), Stripe (payments), OpenAI (planning and image operations), ElevenLabs (speech), PostHog (product analytics), Google Analytics and Google Ads (consented traffic and conversion measurement), infrastructure and storage providers. They receive the data needed for their function and act under their own terms or data-processing commitments.
Some providers may process data outside your country. Where required, we use an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism and apply appropriate safeguards. Provider privacy notices explain their locations and independent processing in more detail.
We may disclose data where required by law, to protect users or the service, in a corporate transaction with appropriate safeguards, or when you direct us to share it. We do not sell personal data.
Retention and security
We keep account and active project data while the account exists. Deleted content may remain for a limited recovery, backup, security or dispute period before removal. Credit and billing records may be retained for the period required by tax, accounting and fraud-prevention law.
We use access controls, account isolation, transport security and operational safeguards designed to protect data. No online service can guarantee absolute security; protect your sign-in and contact us if you suspect misuse.
Your rights
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. You may also complain to your local data-protection authority.
To exercise a right, contact support@shortsly.io. We may need to verify the request. Account deletion controls provide a direct way to remove the account and begin deletion of its projects and media.
Cookies, local storage and analytics
Essential cookies and browser storage support authentication, security, your privacy choices, theme and work in progress. Optional analytics is off until you allow it. The Analytics choice enables PostHog and Google Analytics to measure visits, sign-ups, product usage and purchases. Session recordings are disabled. The separate Ad measurement choice enables Google Ads conversion measurement; personalised advertising remains disabled.
Only when you allow Ad measurement and enhanced conversions are configured does Google normalize and hash the signed-in account email to match a purchase to an ad interaction. Analytics consent alone does not enable this. The unhashed address is not included in the conversion event stored by Shortsly.
Choose Reject to keep only essential storage, Preferences to choose purposes separately, or Accept all to allow both optional purposes. Reopen Cookie preferences in the website footer, on policy pages or in app Settings. We remember the choice for up to 180 days across shortsly.io and app.shortsly.io in this browser, and record its version and date for signed-in accounts so optional server-side analytics respects it. Withdrawing consent stops future optional collection and clears accessible measurement identifiers; it does not erase earlier records. Necessary account, billing and security records remain separate from optional analytics.
Children and changes
Shortsly is not directed to children who cannot lawfully consent to or enter the service agreement in their country. Do not submit a child's personal data without a lawful basis and all required permissions.
We may update this policy as the service or law changes. We will identify the latest date and provide additional notice for a material change.